What is CVE-2026-66635?
CVE-2026-66635 is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability affecting the Slider by 10Web plugin versions up to 1.2.62. This flaw could allow an attacker to perform unauthorized actions on behalf of a legitimate user. Users are advised to apply updates for the plugin as a mitigation.
Azərbaycanca: CVE-2026-66635, 10Web şirkətinin Slider plagininin 1.2.62 və daha əvvəlki versiyalarında aşkarlanmış, autentifikasiya tələb etməyən (unauthenticated) Cross Site Request Forgery (CSRF) zəifliyidir. Bu zəiflik təcavüzkara istifadəçinin adından icazəsiz əməliyyatlar icra etməyə imkan verə bilər. İstifadəçilərə plaginə dair yeniləmələri tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the Slider by 10Web plugin are affected by CVE-2026-66635?
This vulnerability affects plugin versions up to and including 1.2.62.
Is authentication required to exploit CVE-2026-66635?
No, this is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability, meaning it does not require authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.